Vulnerability Description
Minetest before 5.4.0 allows attackers to add or modify arbitrary meta fields of the same item stack as saved user input, aka ItemStack meta injection.
CVSS Score
CRITICAL
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Minetest | Minetest | < 5.4.0 |
| Debian | Debian Linux | 10.0 |
References
- https://bugs.debian.org/1004223Mailing ListPatchThird Party Advisory
- https://github.com/minetest/minetest/commit/b5956bde259faa240a81060ff4e598e25ad5PatchThird Party Advisory
- https://github.com/minetest/minetest/security/advisories/GHSA-hwj2-xf72-r4cfPatchThird Party Advisory
- https://www.debian.org/security/2022/dsa-5075Mailing ListThird Party Advisory
- https://bugs.debian.org/1004223Mailing ListPatchThird Party Advisory
- https://github.com/minetest/minetest/commit/b5956bde259faa240a81060ff4e598e25ad5PatchThird Party Advisory
- https://github.com/minetest/minetest/security/advisories/GHSA-hwj2-xf72-r4cfPatchThird Party Advisory
- https://www.debian.org/security/2022/dsa-5075Mailing ListThird Party Advisory
FAQ
What is CVE-2022-24300?
CVE-2022-24300 is a vulnerability with a CVSS score of 9.8 (CRITICAL). Minetest before 5.4.0 allows attackers to add or modify arbitrary meta fields of the same item stack as saved user input, aka ItemStack meta injection.
How severe is CVE-2022-24300?
CVE-2022-24300 has been rated CRITICAL with a CVSS base score of 9.8/10. This is considered a critical vulnerability requiring immediate attention.
Is there a patch for CVE-2022-24300?
Check the references section above for vendor advisories and patch information. Affected products include: Minetest Minetest, Debian Debian Linux.